Matrix/Persistence/T-6004
T-6004validatedactive

Skill/Plugin Backdoor

Install a backdoored skill or plugin that persists across agent restarts

Tactic

Persistence (Stage 6)

Establish persistent access surviving restarts and session changes

Attack Class

SKILL-FRONTMATTER

Embedding malicious instructions in skill or plugin metadata and description fields

Evidence

validated

Reproduced in controlled lab environment (DVAA) with documented steps.

DVAA Validation

skill-backdoor-install

Honeypot Coverage (AgentPwn)

Queuedsupply-chain

In scope for honeypot observation; trap page or telemetry hook not yet built.

Supply-chain trap page not yet built.

Detection (HackMyAgent)

Live6 live · 0 queued
SKILL-001SKILL-002SKILL-003SKILL-004SKILL-005SKILL-006
npx hackmyagent secure --ciLive = check implemented in hackmyagent; queued = declared, not yet implemented

Defense (OASB Controls)

Live4 live · 0 queued
Live = documented at oasb.ai; queued = declared, not yet documented

How to Cite

AI Agent Threat Matrix T-6004 (Skill/Plugin Backdoor). OpenA2A, 2026. https://threats.opena2a.org/techniques/T-6004